Brent$101.25(≈RM413)▲ +0.99%WTI$91.84(≈RM375)▲ +0.78%Nat Gas$2.99(≈RM12)▲ +2.05%Bunker$858.50(≈RM3,503)▲ +0.18%Tapis$86.75(≈RM354)JKM LNG$26.05(≈RM106)▲ +0.23%MGO$1310.00(≈RM5,345)▼ -3.03%EU Carbon€86.73(≈RM404)▲ +0.16%TTF Gas€73.39(≈RM342)▲ +4.44%Diesel$4.83(≈RM20)▼ -1.23%Coal$144.00(≈RM588)USD/MYR4.0800▲ +0.15%US Rigs551▲ +7 M/MRON95RM4.57(≈US$1.12)▲ +4.58% W/WRON97RM5.05(≈US$1.24)▲ +4.12% W/WDieselRM5.42(≈US$1.33)▲ +2.85% W/W
22:12 MYT
CommoditiesLife-SavingFirefightingManpowerPaintingDormitoryUAV TrainingConsultancy

Cyber Risk in the Safety Management System: What MSC.428(98) Actually Requires

Cyber risk stopped being an IT question in January 2021. It became an ISM Code question, which means it is audited by the same people, on the same cycle, with the same consequences as a fire drill record. Most companies still answer it as though it were about software.

By  · 
 · 
9 mins read

Bridge crew communicating

The Decision That Changed the Question

IMO Resolution MSC.428(98) did something more consequential than issue a cyber security requirement. It declined to create a separate cyber instrument at all, and instead required that cyber risks be addressed within the existing safety management system, with compliance to be demonstrated no later than the first annual verification of the company’s Document of Compliance after 1 January 2021.

That choice determines everything else. A standalone cyber regulation would have needed its own certificates, its own surveyors, and its own enforcement machinery, all of which take years to build. Placing the obligation inside the ISM Code meant it inherited machinery that already existed and already had teeth: internal audits, DOC annual verification, management review, and port State control’s ability to raise a non-conformity.

The IMO did not build a cyber regime. It put cyber risk inside the one regime that already had auditors, certificates and the power to hold a ship.

The practical consequence is that cyber compliance is assessed by ISM auditors asking ISM questions, not by security specialists running technical tests. The question is not whether your defences are sophisticated. It is whether risks were identified, safeguards established, procedures documented, crew familiarised, and the whole thing reviewed, which is what the ISM Code asks about every other hazard aboard.

Why “We Have Antivirus” Fails

The most common inadequate answer treats the requirement as a procurement question. Antivirus is installed, the firewall is configured, the crew have been told not to use personal USB drives, and the company considers the matter addressed.

It fails for a structural reason. The ISM Code does not ask what products you bought. It requires that risks be identified and that safeguards be established against them, which means the starting point is a risk assessment naming this ship’s systems, not a list of controls. An auditor who finds a generic cyber policy with no ship-specific systems named, no ranking of which risks matter most, and no evidence that the crew know their part in it, has found a document that describes an intention rather than a system.

The second reason is scope. Antivirus protects information technology. The systems that can hurt a ship are operational technology: ECDIS, radar, AIS, GMDSS, engine and cargo automation, ballast control. These are increasingly networked, frequently run software that cannot be patched on a normal cycle, and are serviced by technicians who arrive with laptops and connect them. A control set built for the office network does not touch any of it.

What an Auditor Asks For

A ship-specific risk assessment: Naming the actual systems aboard, with risks ranked rather than listed, and reviewed when the ship’s systems change.

Procedures in the SMS: Cyber procedures sitting inside the safety management system alongside everything else, not in a separate IT manual nobody aboard has read.

Defined responsibilities: Who does what, aboard and ashore, including the company’s designated person and the master’s role.

Familiarisation and training records: Evidence that crew know their responsibilities, in the same way drill records evidence emergency preparedness.

Contingency and recovery: What happens when a system is lost, how the ship navigates or operates without it, and how it recovers. This is the part most often missing.

Third-party control: How technicians and service engineers connect equipment to shipboard systems, and what is required of them before they do.

The IMO’s guidelines on maritime cyber risk management, issued as MSC-FAL.1/Circ.3/Rev.2, structure this around five functions: identify, protect, detect, respond and recover. Companies tend to invest heavily in protect and almost nothing in detect, respond and recover, which is why an auditor asking “how would you know?” and “what then?” so often exposes the gap.

The Class Requirements That Closed the Newbuild Gap

MSC.428(98) governs the management system but says little about how a ship is built. The classification societies filled that gap. IACS adopted two unified requirements, UR E26 covering the cyber resilience of ships as an integrated platform, and UR E27 covering the cyber resilience of on-board systems and equipment, both applying to new ships contracted for construction on or after 1 July 2024.

The split is clean. E26 addresses the ship as a whole, including the secure integration of IT and OT equipment into the vessel’s network across design, construction, commissioning and operational life. E27 addresses individual computer-based systems and the interfaces between them, aiming to ensure integrity is secured and hardened by third-party equipment suppliers. They sit on top of UR E22, the longer-standing requirement covering on-board use of computer-based systems, which categorises systems by the consequences of their failure.

For operators this creates a two-speed fleet. Ships contracted from mid-2024 arrive with cyber resilience built in and surveyable, and their first cyber-relevant in-service surveys are now falling due. Everything older is governed by the SMS obligation alone, which means the management system is carrying the whole weight. A company managing both is managing two different standards, and the one likely to be found wanting is the older tonnage where nothing was designed in.

New ships have cyber resilience engineered into them. Older ships have a policy document. Only one of those gets easier to defend as the audits get sharper.

Where the Non-Conformity Comes From

Because enforcement runs through ordinary ISM machinery, the failure modes look like every other ISM failure, which by now should feel familiar to anyone who has read about firefighting audits or drill records.

Generic Template
A policy that could belong to any ship, with no systems named and no risks ranked.

IT Only
Controls covering the office network while ECDIS, automation and cargo systems go unaddressed.

No Crew Familiarity
Procedures nobody aboard can describe, which fails the same test as an unrehearsed drill.

No Recovery Plan
Nothing describing how the ship operates with a system lost, or how it is restored.

Uncontrolled Access
Service engineers connecting laptops to OT systems with no procedure governing it.

Never Reviewed
A risk assessment dated at first implementation and untouched since, despite system changes.

A port State control officer who finds a cyber risk assessment that is a generic template, with no ship-specific systems named, no risk ranking and no evidence of crew familiarity, can raise a non-conformity. Where it is serious enough, that reaches the ship. This is the strength of putting cyber inside the ISM Code rather than beside it: the consequences are the ordinary ISM consequences, and they were already understood.

Making It Auditable

The work is narrower than it sounds. Write a risk assessment that names the systems this ship actually has, ranks the risks, and gets reviewed when equipment changes. Put the procedures inside the SMS rather than in a separate manual. Assign responsibilities to named roles aboard and ashore. Familiarise the crew and record it, exactly as with any other safety procedure. Write the contingency and recovery side properly, because that is where auditors find the hole. Control how third parties connect to shipboard equipment. And review the whole thing on the management review cycle rather than treating it as a one-off implementation project.

Done that way, cyber risk is maintained on the same rhythm as fire drills and lifeboat servicing, which is precisely what the resolution intended. Done as an IT project, it produces a document that satisfies nobody, on a subject where the consequence of being wrong is a ship that cannot navigate, load, or discharge.

Frequently Asked Questions

What does MSC.428(98) require?

That cyber risks be appropriately addressed within the ship’s safety management system under the ISM Code, demonstrated no later than the first annual verification of the company’s Document of Compliance after 1 January 2021. It deliberately does not create a separate cyber instrument, so compliance is verified through existing ISM machinery: internal audit, DOC verification, management review, and port State control.

Is a separate cyber security management system required?

No. The requirement is to integrate cyber risk management into the existing safety management system rather than to build a standalone regime. In practice that means the risk assessment, procedures, responsibilities, training records and contingency arrangements sit inside the SMS alongside other safety procedures, where auditors expect to find them.

What are IACS UR E26 and E27, and do they apply to my ship?

They are classification society unified requirements on cyber resilience. UR E26 covers the ship as an integrated platform, including secure integration of IT and OT equipment across design, construction, commissioning and operational life; UR E27 covers individual on-board systems and equipment and the requirements placed on third-party suppliers. Both apply to new ships contracted for construction on or after 1 July 2024, so existing tonnage remains governed by the SMS obligation alone.

Why is antivirus not sufficient?

Because the ISM Code asks whether risks were identified and safeguards established, not what products were purchased. A control list with no ship-specific risk assessment behind it does not demonstrate that. Antivirus also addresses information technology, while the systems that affect safety are operational technology such as ECDIS, automation and cargo control, which are networked, often unpatchable on a normal cycle, and accessed by visiting service technicians.

compliance
regulation
imo
solas
inspections
maritime-safety
maritime-operations
maritime-technology

Sources: IMO Resolution MSC.428(98), Maritime Cyber Risk Management in Safety Management Systems, requiring cyber risks to be addressed in the SMS no later than the first annual verification of the company’s Document of Compliance after 1 January 2021 · IMO MSC-FAL.1/Circ.3/Rev.2, Guidelines on Maritime Cyber Risk Management (identify, protect, detect, respond, recover) · IACS Unified Requirement E26, Cyber resilience of ships, and Unified Requirement E27, Cyber resilience of on-board systems and equipment, both applicable to ships contracted for construction on or after 1 July 2024 · IACS Unified Requirement E22, On Board Use and Application of Computer Based Systems · IMO ISM Code (Resolution A.741(18)), Sections 1, 7, 8 and 12